SecurityFocus Newsletter #332
Peter Laborge <[email protected]> Tue, 10 Jan 2006 16:43:48 -0700
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #332
----------------------------------------
This Issue is Sponsored By: SpiDynamics
ALERT: Learn to Think Like a Hacker- Simulate a Hacker Breaking into Your Web Apps
The speed with which Web Applications are developed make them prime targets for attackers, often these applications were developed so quickly that they are not coded properly or subjected to any security testing. Hackers know this and use it as their weapon. Download this *FREE* test guide from SPI Dynamics to check for Web application vulnerabilities.
https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003P6V
------------------------------------------------------------------
I. FRONT AND CENTER
1. Windows rootkits of 2005, part three
2. Patching a broken Windows
II. BUGTRAQ SUMMARY
1. MTink Home Environment Variable Buffer Overflow Vulnerability
2. MyBB Print Thread Script HTML Injection Vulnerability
3. MyBB File Upload SQL Injection Vulnerability
4. IBM AIX GetShell and GetCommand File Enumeration Vulnerability
5. IBM AIX GetShell and GetCommand Partial File Disclosure Vulnerability
6. InTouch User Variable SQL Injection Vulnerability
7. PHPJournaler Readold Variable SQL Injection Vulnerability
8. Chimera Web Portal Multiple Input Validation Vulnerabilities
9. B-Net Multiple HTML Injection Vulnerabilities
10. ScozNet ScozBook AdminName Variable SQL Injection Vulnerability
11. VBulletin Event Title HTML Injection Vulnerability
12. Drupal URL-Encoded Input HTML Injection Vulnerability
13. File::ExtAttr Extended File Attribute Off-By-One Buffer Overflow Vulnerability
14. DiscusWare Discus Error Message Cross-Site Scripting Vulnerability
15. Gentoo Pinentry Local Privilege Escalation Vulnerability
16. INCOGEN Bugport Multiple SQL Injection Vulnerabilities
17. SCO OpenServer Termsh Buffer Overflow Vulnerability
18. INCOGEN Bugport Index.PHP Multiple Cross-Site Scripting Vulnerabilities
19. EFileGo Multiple Input Validation Vulnerabilities
20. Primo Place Primo Cart Multiple SQL Injection Vulnerabilities
21. Valdersoft Shopping Cart Remote File Include Vulnerability
22. Intel Graphics Accelerator Driver Remote Denial Of Service Vulnerability
23. Linux Kernel SET_MEMPOLICY Local Denial of Service Vulnerability
24. ESRI ArcPad APM File Processing Buffer Overflow Vulnerability
25. IDV Directory Viewer Index.PHP Information Disclosure Vulnerability
26. raSMP User-Agent HTML Injection Vulnerability
27. Linux Kernel FIB_LOOKUP Denial of Service Vulnerability
28. Lizard Cart CMS Multiple SQL Injection Vulnerabilities
29. Linux Kernel Sysctl_String Local Buffer Overflow Vulnerability
30. Linux Kernel DVB Driver Local Buffer Overflow Vulnerability
31. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
32. OpenBSD DEV/FD Arbitrary File Access Vulnerability
33. PHP MySQL_Connect Remote Buffer Overflow Vulnerability
34. Apple AirPort Remote Denial of Service Vulnerability
35. Blue Coat Systems WinProxy Remote Host Header Buffer Overflow Vulnerability
36. Blue Coat Systems WinProxy Remote Denial Of Service Vulnerability
37. Blue Coat Systems WinProxy Telnet Remote Denial Of Service Vulnerability
38. HylaFAX Remote PAM Authentication Bypass Vulnerability
39. Hylafax Multiple Scripts Remote Command Execution Vulnerability
40. Apache mod_auth_pgsql Multiple Format String Vulnerabilities
41. Foro Domus Multiple Input Validation Vulnerabilities
42. OnePlug CMS Multiple SQL Injection Vulnerabilities
43. iNETstore Online Search Cross-Site Scripting Vulnerability
44. ADN Forum Multiple Input Validation Vulnerabilities
45. IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities
46. Timecan CMS ViewID SQL Injection Vulnerability
47. Modular Merchant Shopping Cart Cross-Site Scripting Vulnerability
48. TheWebForum Multiple Input Validation Vulnerabilities
49. Aquifer CMS Index.ASP Cross-Site Scripting Vulnerability
50. TinyPHPForum Multiple Directory Traversal Vulnerabilities
51. NetSarang XLPD Remote Denial of Service Vulnerability
52. Navboard Multiple BBCode Tag Script Injection Vulnerabilities
III. SECURITYFOCUS NEWS
1. Security flaws on the rise, questions remain
2. Data security moves front and center in 2005
3. Sober virus scares up child-porn confession
4. Researchers: Flaw auctions would improve security
5. Skype under scrutiny for bugs
6. Say hello to the Skype Trojan
7. Shared music abuse bug hits iTunes
8. US cybersecurity all at sea
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Security Director, New York City
2. [SJ-JOB] Manager, Information Security, Lanham
3. [SJ-JOB] Sales Engineer, Metro DC
4. [SJ-JOB] Sales Engineer, London
5. [SJ-JOB] Sales Engineer, New York Area
6. [SJ-JOB] Security Architect, Calgary
7. [SJ-JOB] Privacy Officer, Tysons Corner
8. [SJ-JOB] Certification & Accreditation Engineer, Washington
9. [SJ-JOB] Security Product Manager, Mountain View
10. [SJ-JOB] Sales Engineer, Los Angeles
11. [SJ-JOB] Management, Crystal City
12. [SJ-JOB] Management, Crystal City
13. [SJ-JOB] Security Engineer, Mountain View
14. [SJ-JOB] Director, Information Security, New York
15. [SJ-JOB] Management, Crystal City
16. [SJ-JOB] Management, Crystal City
17. [SJ-JOB] Management, McLean
18. [SJ-JOB] Sr. Security Engineer, San Jose
19. [SJ-JOB] Security Engineer, Chicago Suburbs
20. [SJ-JOB] Sr. Security Engineer, San Jose
21. [SJ-JOB] Security Product Marketing Manager, San Jose
22. [SJ-JOB] Security Architect, San Jose
23. [SJ-JOB] Channel / Business Development, North Canton
24. [SJ-JOB] Application Security Engineer, San Jose
25. [SJ-JOB] Security Engineer, San Jose
26. [SJ-JOB] Security Engineer, Austin
27. [SJ-JOB] Compliance Officer, Camarillo
28. [SJ-JOB] Jr. Security Analyst, Princeton
29. [SJ-JOB] Sr. Security Analyst, Parsippany
30. [SJ-JOB] Sr. Security Engineer, Dublin
31. [SJ-JOB] Sr. Security Analyst, Scottsdale
32. [SJ-JOB] Security Consultant, South Brunswick
33. [SJ-JOB] Sales Engineer, Chicago
34. [SJ-JOB] Security Consultant, Dallas
35. [SJ-JOB] Management, Toronto
36. [SJ-JOB] Account Manager, Detroit/Southfield
37. [SJ-JOB] Application Security Architect, Maidenhead/ London
38. [SJ-JOB] Security Consultant, Frankfurt or Munich
39. [SJ-JOB] Security Engineer, Santa Clara
40. [SJ-JOB] Sr. Security Engineer, Dublin
41. [SJ-JOB] Technical Writer, Columbia
42. [SJ-JOB] Security Engineer, Dublin
43. [SJ-JOB] Sales Engineer, Any City
V. INCIDENTS LIST SUMMARY
1. WMF Threat OK , but no huge attack ... WHY ?
2. WMF Vulnerability Summary
VI. VULN-DEV RESEARCH LIST SUMMARY
1. WMF exploitation FAQ
2. RECON2006 - Call for paper
3. Did MS pull an Ilfak? (MS patch bindiff results)
4. Windows CE Address Book 2
5. Uninformed Journal Release Announcement: Volume 3
6. WMF - read Win3.1SDK Help!
VII. MICROSOFT FOCUS LIST SUMMARY
1. patching servers...
2. audit trails for file access
3. SecurityFocus Microsoft Newsletter #272
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. Hide internal address (Postfix)
2. IPS project - wanted translators
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Windows rootkits of 2005, part three
By James Butler, Sherri Sparks
The third and final article in this series explores five different rootkit detection techniques used to discover Windows rootkit deployments. Additionally, nine different tools designed for administrators are discussed.
http://www.securityfocus.com/infocus/1854
2. Patching a broken Windows
By Robert Lemos
Robert Lemos interviews Datarescue's senior software developer Ilfak Guilfanov, the creator of the unofficial patch for the flaw in the Windows Meta File format that saw tens of thousands of downloads prior to the official patch release by Microsoft. Guilfanov explains why he decided to issue a patch for the vulnerability, how he created the patch, and his thoughts on whether third-party patches are generally a good thing.
http://www.securityfocus.com/columnists/378
II. BUGTRAQ SUMMARY
--------------------
1. MTink Home Environment Variable Buffer Overflow Vulnerability
BugTraq ID: 16095
Remote: No
Date Published: 2005-12-31
Relevant URL: http://www.securityfocus.com/bid/16095
Summary:
A buffer overflow vulnerability affects MTink. This vulnerability may permit local attackers to execute arbitrary code with superuser privileges.
2. MyBB Print Thread Script HTML Injection Vulnerability
BugTraq ID: 16096
Remote: Yes
Date Published: 2005-12-31
Relevant URL: http://www.securityfocus.com/bid/16096
Summary:
MyBB (MyBulletinBoard) is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
3. MyBB File Upload SQL Injection Vulnerability
BugTraq ID: 16097
Remote: Yes
Date Published: 2005-12-31
Relevant URL: http://www.securityfocus.com/bid/16097
Summary:
MyBB (MyBulletinBoard) is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
4. IBM AIX GetShell and GetCommand File Enumeration Vulnerability
BugTraq ID: 16102
Remote: No
Date Published: 2005-12-31
Relevant URL: http://www.securityfocus.com/bid/16102
Summary:
IBM AIX is prone to a local vulnerability in getShell and getCommand. This issue may let local attackers enumerate the existence of files on the computer that they wouldn't ordinarily be able to see.
5. IBM AIX GetShell and GetCommand Partial File Disclosure Vulnerability
BugTraq ID: 16103
Remote: No
Date Published: 2006-01-01
Relevant URL: http://www.securityfocus.com/bid/16103
Summary:
IBM AIX is prone to a local vulnerability in getShell and getCommand. This vulnerability may let the attacker gain unauthorized read access to shell scripts on the computer.
6. InTouch User Variable SQL Injection Vulnerability
BugTraq ID: 16110
Remote: Yes
Date Published: 2006-01-01
Relevant URL: http://www.securityfocus.com/bid/16110
Summary:
inTouch is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
7. PHPJournaler Readold Variable SQL Injection Vulnerability
BugTraq ID: 16111
Remote: Yes
Date Published: 2006-01-01
Relevant URL: http://www.securityfocus.com/bid/16111
Summary:
PHPjournaler is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
8. Chimera Web Portal Multiple Input Validation Vulnerabilities
BugTraq ID: 16113
Remote: Yes
Date Published: 2006-01-01
Relevant URL: http://www.securityfocus.com/bid/16113
Summary:
Chimera Web Portal is prone to multiple input validation vulnerabilities. The issues include cross-site scripting and SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
9. B-Net Multiple HTML Injection Vulnerabilities
BugTraq ID: 16114
Remote: Yes
Date Published: 2006-01-02
Relevant URL: http://www.securityfocus.com/bid/16114
Summary:
B-Net Software is prone to multiple HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
10. ScozNet ScozBook AdminName Variable SQL Injection Vulnerability
BugTraq ID: 16115
Remote: Yes
Date Published: 2006-01-02
Relevant URL: http://www.securityfocus.com/bid/16115
Summary:
ScozNet ScozBook is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
11. VBulletin Event Title HTML Injection Vulnerability
BugTraq ID: 16116
Remote: Yes
Date Published: 2006-01-01
Relevant URL: http://www.securityfocus.com/bid/16116
Summary:
vBulletin is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
This issue is reported to affect vBulletin 3.5.2. Earlier versions may also be affected.
12. Drupal URL-Encoded Input HTML Injection Vulnerability
BugTraq ID: 16117
Remote: Yes
Date Published: 2006-01-01
Relevant URL: http://www.securityfocus.com/bid/16117
Summary:
Drupal is prone to an HTML injection vulnerability when handling URL-encoded HTML and script code in message content. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
13. File::ExtAttr Extended File Attribute Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 16118
Remote: No
Date Published: 2006-01-02
Relevant URL: http://www.securityfocus.com/bid/16118
Summary:
File::ExtAttr is prone to an off-by-one buffer overflow vulnerability. This issue may occur when the module is used to read extended file attributes of untrusted files.
Exploitation of the issue could potentially result in a denial of service in the module or may allow for execution of arbitrary code.
14. DiscusWare Discus Error Message Cross-Site Scripting Vulnerability
BugTraq ID: 16119
Remote: Yes
Date Published: 2006-01-02
Relevant URL: http://www.securityfocus.com/bid/16119
Summary:
DiscusWare Discus is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
15. Gentoo Pinentry Local Privilege Escalation Vulnerability
BugTraq ID: 16120
Remote: No
Date Published: 2006-01-03
Relevant URL: http://www.securityfocus.com/bid/16120
Summary:
pinentry is prone to a local privilege escalation vulnerability.
Successful exploitation can allow a pinentry user to read or write arbitrary files with the privileges of group ID 0.
16. INCOGEN Bugport Multiple SQL Injection Vulnerabilities
BugTraq ID: 16121
Remote: Yes
Date Published: 2006-01-03
Relevant URL: http://www.securityfocus.com/bid/16121
Summary:
Bugport is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
17. SCO OpenServer Termsh Buffer Overflow Vulnerability
BugTraq ID: 16122
Remote: No
Date Published: 2006-01-03
Relevant URL: http://www.securityfocus.com/bid/16122
Summary:
SCO OpenServer termsh application is affected by a local buffer overflow vulnerability.
A successful attack may allow the attacker to gain elevated privileges in the context of the application. It should be noted that the application is installed as setgid auth.
SCO OpenServer 5.0.x are affected by this issue.
18. INCOGEN Bugport Index.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16123
Remote: Yes
Date Published: 2006-01-03
Relevant URL: http://www.securityfocus.com/bid/16123
Summary:
Bugport is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
19. EFileGo Multiple Input Validation Vulnerabilities
BugTraq ID: 16124
Remote: Yes
Date Published: 2006-01-03
Relevant URL: http://www.securityfocus.com/bid/16124
Summary:
eFileGo is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to retrieve arbitrary files, upload files to arbitrary locations, cause denial of service conditions and execute arbitrary commands.
Successful exploitation may facilitate a remote compromise of the computer running the affected software.
20. Primo Place Primo Cart Multiple SQL Injection Vulnerabilities
BugTraq ID: 16125
Remote: Yes
Date Published: 2006-01-03
Relevant URL: http://www.securityfocus.com/bid/16125
Summary:
Primo Cart is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Version 1.0 and prior are affected; other versions may also be vulnerable.
21. Valdersoft Shopping Cart Remote File Include Vulnerability
BugTraq ID: 16126
Remote: Yes
Date Published: 2006-01-03
Relevant URL: http://www.securityfocus.com/bid/16126
Summary:
Valdersoft Shopping Cart is prone to a remote file include vulnerability.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the Web server process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
22. Intel Graphics Accelerator Driver Remote Denial Of Service Vulnerability
BugTraq ID: 16127
Remote: Yes
Date Published: 2006-01-03
Relevant URL: http://www.securityfocus.com/bid/16127
Summary:
The Intel Graphics Accelerator driver is susceptible to a remote denial of service vulnerability. This issue is demonstrated to occur when the affected driver attempts to display an overly long text in a text area.
This issue allows attackers to crash the display manager on Microsoft Windows XP, or cause a complete system crash on computers running Microsoft Windows 2000. Other operating systems where the affected display driver is available are also likely affected.
Version 6.14.10.4308 of the Intel Graphics Accelerator driver is considered vulnerable to this issue. Other versions may also be affected.
This issue will be updated as further information becomes available. This issue may be related to the one described in BID 10913 (Microsoft Windows Large Image Processing Remote Denial Of Service Vulnerability), but this has not been confirmed.
23. Linux Kernel SET_MEMPOLICY Local Denial of Service Vulnerability
BugTraq ID: 16135
Remote: No
Date Published: 2006-01-04
Relevant URL: http://www.securityfocus.com/bid/16135
Summary:
Linux kernel is prone to a local denial of service vulnerability.
This issue affects the 'set_mempolicy' function of the 'mm/mempolicy.c' file.
Successful exploitation causes the kernel to crash, leading to a denial of service condition.
24. ESRI ArcPad APM File Processing Buffer Overflow Vulnerability
BugTraq ID: 16136
Remote: Yes
Date Published: 2006-01-04
Relevant URL: http://www.securityfocus.com/bid/16136
Summary:
ArcPad is prone to a buffer overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows an attacker to execute arbitrary machine code in the context of the user utilizing the affected application.
25. IDV Directory Viewer Index.PHP Information Disclosure Vulnerability
BugTraq ID: 16137
Remote: Yes
Date Published: 2006-01-04
Relevant URL: http://www.securityfocus.com/bid/16137
Summary:
IDV Directory Viewer is prone to an information disclosure vulnerability.
This vulnerability may be used to disclose file information in the Web server root. Information obtained may be helpful in further attacks.
Versions prior to 2005.1 are vulnerable; other versions may also be affected.
26. raSMP User-Agent HTML Injection Vulnerability
BugTraq ID: 16138
Remote: Yes
Date Published: 2006-01-04
Relevant URL: http://www.securityfocus.com/bid/16138
Summary:
raSMP is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
27. Linux Kernel FIB_LOOKUP Denial of Service Vulnerability
BugTraq ID: 16139
Remote: Yes
Date Published: 2006-01-04
Relevant URL: http://www.securityfocus.com/bid/16139
Summary:
Linux kernel is prone to a denial of service vulnerability.
This issue arises when the kernel handles specially crafted fib_lookup netlink messages.
Successful exploitation may allow remote attackers to trigger a denial of service condition. Local exploitation may be possible as well.
28. Lizard Cart CMS Multiple SQL Injection Vulnerabilities
BugTraq ID: 16140
Remote: Yes
Date Published: 2006-01-04
Relevant URL: http://www.securityfocus.com/bid/16140
Summary:
Lizard Cart CMS is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
29. Linux Kernel Sysctl_String Local Buffer Overflow Vulnerability
BugTraq ID: 16141
Remote: No
Date Published: 2006-01-04
Relevant URL: http://www.securityfocus.com/bid/16141
Summary:
Linux kernel is prone to a local buffer overflow vulnerability. This issue is due to an off-by-one error in the sysctl subsystem.
A successful attack may result in a denial of service condition or possibly arbitrary code execution in the context of the local kernel.
Linux kernel versions prior to 2.6.15 in the 2.6 series are considered vulnerable to this issue.
30. Linux Kernel DVB Driver Local Buffer Overflow Vulnerability
BugTraq ID: 16142
Remote: No
Date Published: 2006-01-04
Relevant URL: http://www.securityfocus.com/bid/16142
Summary:
Linux kernel is prone to a local buffer overflow vulnerability. This issue is due to a flaw in the DVB (Digital Video Broadcasting) driver subsystem. This issue is only exploitable on computers with the affected DVB module compiled, enabled, and accessible to local malicious users.
A successful attack may result in a denial of service condition or possibly arbitrary code execution in the context of the local kernel.
Linux kernel versions prior to 2.6.15 in the 2.6 series are considered vulnerable to this issue.
31. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPdf and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.
Specific details of these issues are not currently available. This record will be updated when more information becomes available.
kdegraphics and KPdf versions 3.4.3 and earlier and KOffice and KWord versions 1.4.2 and earlier are vulnerable.
32. OpenBSD DEV/FD Arbitrary File Access Vulnerability
BugTraq ID: 16144
Remote: No
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16144
Summary:
OpenBSD is prone to a vulnerability that allows local attackers to gain access to arbitrary files.
This could allow attackers to obtain sensitive information, which may be used to carry out other attacks against a vulnerable computer.
This issue reportedly affects OpenBSD 3.7 and 3.8. Other versions may be vulnerable as well.
33. PHP MySQL_Connect Remote Buffer Overflow Vulnerability
BugTraq ID: 16145
Remote: Yes
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16145
Summary:
PHP is prone to a remote buffer overflow vulnerability.
An attacker can exploit this issue to execute arbitrary machine code in the context of the affected Web server. Failed exploit attempts will likely result in crashing the Web server, denying service to legitimate users.
It should be noted that arguments to the 'mysql_connect' function are not usually accessible for modification by remote attackers. This may limit the possible exploitation to legitimate users and administrators in a shared hosting environment.
PHP for Microsoft Windows versions 4.3.10, 4.4.0, and 4.4.1 are vulnerable; other versions may also be affected.
34. Apple AirPort Remote Denial of Service Vulnerability
BugTraq ID: 16146
Remote: Yes
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16146
Summary:
Apple AirPort firmware is prone to a denial of service condition. This occurs when the device handles malformed packets.
Specific details regarding this issue are not currently known. This record will be updated when more information becomes available.
AirPort Express firmware versions prior to 6.3 and AirPort Extreme firmware versions prior to 5.7 are vulnerable.
35. Blue Coat Systems WinProxy Remote Host Header Buffer Overflow Vulnerability
BugTraq ID: 16147
Remote: Yes
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16147
Summary:
A remote buffer overflow vulnerability affects Blue Coat Systems WinProxy. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Blue Coat Systems WinProxy version 6.0 is vulnerable to this issue; other versions may also be affected.
36. Blue Coat Systems WinProxy Remote Denial Of Service Vulnerability
BugTraq ID: 16148
Remote: Yes
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16148
Summary:
WinProxy is prone to a remote denial of service vulnerability. This issue is due to a failure in the application to properly handle user-supplied data.
A remote attacker can exploit this issue to crash the server denying service to legitimate users.
This issue is reported to affect WinProxy version 6.0; other versions may also be vulnerable.
37. Blue Coat Systems WinProxy Telnet Remote Denial Of Service Vulnerability
BugTraq ID: 16149
Remote: Yes
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16149
Summary:
WinProxy is prone to a remote denial of service vulnerability. This issue is due to a failure in the application to properly handle user-supplied data.
A remote attacker can exploit this issue to crash the server denying service to legitimate users. Remote code execution may be possible but is unlikely.
This issue affects WinProxy version 6.0; earlier versions are also likely vulnerable.
38. HylaFAX Remote PAM Authentication Bypass Vulnerability
BugTraq ID: 16150
Remote: Yes
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16150
Summary:
The HylaFAX daemon is reported prone to a vulnerability that could allow unauthorized access to the HylaFAX service. It is reported that the issue presents itself due to a flaw in its PAM (Pluggable Authentication Modules) usage.
A remote attacker may exploit this vulnerability to gain unauthorized access to the affected service.
39. Hylafax Multiple Scripts Remote Command Execution Vulnerability
BugTraq ID: 16151
Remote: Yes
Date Published: 2006-01-05
Relevant URL: http://www.securityfocus.com/bid/16151
Summary:
Hylafax is vulnerable to multiple arbitrary command execution vulnerabilities. This issue is due to a failure in the application to properly sanitize user-supplied input.
These vulnerabilities allow an attacker to execute arbitrary commands in the context of the affected application. Successful exploitation may facilitate a compromise of the underlying system.
40. Apache mod_auth_pgsql Multiple Format String Vulnerabilities
BugTraq ID: 16153
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16153
Summary:
mod_auth_pgsql is prone to multiple format string vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in the format-specification argument of formatted printing functions.
These issues could allow remote attackers to execute arbitrary code in the context of the Web server user and gain unauthorized access.
41. Foro Domus Multiple Input Validation Vulnerabilities
BugTraq ID: 16154
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16154
Summary:
Foro Domus is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
Foro Domus version 2.10 is vulnerable to these issues; other versions may also be affected.
42. OnePlug CMS Multiple SQL Injection Vulnerabilities
BugTraq ID: 16155
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16155
Summary:
OnePlug CMS is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
43. iNETstore Online Search Cross-Site Scripting Vulnerability
BugTraq ID: 16156
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16156
Summary:
iNETstore Online is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
44. ADN Forum Multiple Input Validation Vulnerabilities
BugTraq ID: 16157
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16157
Summary:
ADN Forum is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials and allow an attacker to control how the site is rendered to the user. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
45. IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities
BugTraq ID: 16158
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16158
Summary:
IBM Lotus Domino and Notes are prone to multiple unspecified vulnerabilities. Exploitation of these issues results in a failure of the server, thus denying service to legitimate users.
Lotus Domino and Notes versions prior to 6.5.5 are considered vulnerable.
46. Timecan CMS ViewID SQL Injection Vulnerability
BugTraq ID: 16159
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16159
Summary:
Timecan CMS is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
47. Modular Merchant Shopping Cart Cross-Site Scripting Vulnerability
BugTraq ID: 16160
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16160
Summary:
Modular Merchant Shopping Cart is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
48. TheWebForum Multiple Input Validation Vulnerabilities
BugTraq ID: 16161
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16161
Summary:
TheWebForum is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials and allow an attacker to control how the site is rendered to the user. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
49. Aquifer CMS Index.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 16162
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16162
Summary:
Aquifer CMS is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
50. TinyPHPForum Multiple Directory Traversal Vulnerabilities
BugTraq ID: 16163
Remote: Yes
Date Published: 2006-01-06
Relevant URL: http://www.securityfocus.com/bid/16163
Summary:
TinyPHPForum is prone to multiple directory traversal vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the Web server process. Information obtained may aid in further attacks; other attacks are also possible.
These issues are reported to affect version 3.6; earlier versions may also be vulnerable.
51. NetSarang XLPD Remote Denial of Service Vulnerability
BugTraq ID: 16164
Remote: Yes
Date Published: 2006-01-07
Relevant URL: http://www.securityfocus.com/bid/16164
Summary:
Xlpd is prone to a remote denial of service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.
A remote attacker can exploit this issue to crash the affected application effectively denying service to legitimate users.
This issue is reported to affect Xlpd version 2.1; other versions may also be vulnerable.
52. Navboard Multiple BBCode Tag Script Injection Vulnerabilities
BugTraq ID: 16165
Remote: Yes
Date Published: 2006-01-07
Relevant URL: http://www.securityfocus.com/bid/16165
Summary:
Navboard is prone to multiple script injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input prior to including it in dynamically generated content.
Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. Other attacks are also possible.
These issues are reported to affect versions V16 and V17beta2; other versions may also be vulnerable.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Security flaws on the rise, questions remain
By: Robert Lemos
After three years of modest or no gains, the number of publicly reported vulnerabilities jumped in 2005, boosted by easy-to-find bugs in Web applications. Yet, questions remain about the value of analyzing current databases, whose data rarely correlates easily.
http://www.securityfocus.com/news/11367
2. Data security moves front and center in 2005
By: Robert Lemos
YEAR IN REVIEW: High-profile data breaches leaked more than 50 million database records in the United States, while phishing, bot networks, and targeted Trojan horses compromised millions of PCs worldwide.
http://www.securityfocus.com/news/11366
3. Sober virus scares up child-porn confession
By: Robert Lemos
A 20-year-old German man turned himself in to authorities after receiving a copy of the mass-mailing virus, which arrives attached to an e-mail message claiming that law enforcement is investigating the recipient.
http://www.securityfocus.com/news/11365
4. Researchers: Flaw auctions would improve security
By: Robert Lemos
Online auctioneer eBay pulls a seller's second attempt to make money from a vulnerability in Microsoft Excel as security professionals argue that a free market in vulnerabilities could improve software security.
http://www.securityfocus.com/news/11364
5. Skype under scrutiny for bugs
By: John Leyden
The recent emergence of two sets of serious security vulnerabilities in Skype, the popular VoIP communications software app, couldn't have come at a worse time for the firm.
http://www.securityfocus.com/news/11354
6. Say hello to the Skype Trojan
By: John Leyden
Virus writers are targeting Skype users with a new Trojan that poses as the latest version of the popular VoIP software.
http://www.securityfocus.com/news/11348
7. Shared music abuse bug hits iTunes
By: John Leyden
Security researchers have discovered a vulnerability in Apple's popular iTunes application which might be exploited to interfere with shared music downloads.
http://www.securityfocus.com/news/11347
8. US cybersecurity all at sea
By: John Leyden
US cybersecurity risks are being poorly managed by the Department of Homeland Security, according to a former US presidential information security advisor.
http://www.securityfocus.com/news/11345
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Director, New York City
http://www.securityfocus.com/archive/77/421414
2. [SJ-JOB] Manager, Information Security, Lanham
http://www.securityfocus.com/archive/77/421425
3. [SJ-JOB] Sales Engineer, Metro DC
http://www.securityfocus.com/archive/77/421406
4. [SJ-JOB] Sales Engineer, London
http://www.securityfocus.com/archive/77/421409
5. [SJ-JOB] Sales Engineer, New York Area
http://www.securityfocus.com/archive/77/421405
6. [SJ-JOB] Security Architect, Calgary
http://www.securityfocus.com/archive/77/421267
7. [SJ-JOB] Privacy Officer, Tysons Corner
http://www.securityfocus.com/archive/77/421265
8. [SJ-JOB] Certification & Accreditation Engineer, Washington
http://www.securityfocus.com/archive/77/421272
9. [SJ-JOB] Security Product Manager, Mountain View
http://www.securityfocus.com/archive/77/421266
10. [SJ-JOB] Sales Engineer, Los Angeles
http://www.securityfocus.com/archive/77/421263
11. [SJ-JOB] Management, Crystal City
http://www.securityfocus.com/archive/77/421254
12. [SJ-JOB] Management, Crystal City
http://www.securityfocus.com/archive/77/421252
13. [SJ-JOB] Security Engineer, Mountain View
http://www.securityfocus.com/archive/77/421253
14. [SJ-JOB] Director, Information Security, New York
http://www.securityfocus.com/archive/77/421255
15. [SJ-JOB] Management, Crystal City
http://www.securityfocus.com/archive/77/421251
16. [SJ-JOB] Management, Crystal City
http://www.securityfocus.com/archive/77/421249
17. [SJ-JOB] Management, McLean
http://www.securityfocus.com/archive/77/421250
18. [SJ-JOB] Sr. Security Engineer, San Jose
http://www.securityfocus.com/archive/77/421081
19. [SJ-JOB] Security Engineer, Chicago Suburbs
http://www.securityfocus.com/archive/77/421082
20. [SJ-JOB] Sr. Security Engineer, San Jose
http://www.securityfocus.com/archive/77/421077
21. [SJ-JOB] Security Product Marketing Manager, San Jose
http://www.securityfocus.com/archive/77/421079
22. [SJ-JOB] Security Architect, San Jose
http://www.securityfocus.com/archive/77/421080
23. [SJ-JOB] Channel / Business Development, North Canton
http://www.securityfocus.com/archive/77/421070
24. [SJ-JOB] Application Security Engineer, San Jose
http://www.securityfocus.com/archive/77/421072
25. [SJ-JOB] Security Engineer, San Jose
http://www.securityfocus.com/archive/77/421078
26. [SJ-JOB] Security Engineer, Austin
http://www.securityfocus.com/archive/77/421071
27. [SJ-JOB] Compliance Officer, Camarillo
http://www.securityfocus.com/archive/77/421074
28. [SJ-JOB] Jr. Security Analyst, Princeton
http://www.securityfocus.com/archive/77/420892
29. [SJ-JOB] Sr. Security Analyst, Parsippany
http://www.securityfocus.com/archive/77/420791
30. [SJ-JOB] Sr. Security Engineer, Dublin
http://www.securityfocus.com/archive/77/420792
31. [SJ-JOB] Sr. Security Analyst, Scottsdale
http://www.securityfocus.com/archive/77/420790
32. [SJ-JOB] Security Consultant, South Brunswick
http://www.securityfocus.com/archive/77/420776
33. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/420783
34. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/420753
35. [SJ-JOB] Management, Toronto
http://www.securityfocus.com/archive/77/420754
36. [SJ-JOB] Account Manager, Detroit/Southfield
http://www.securityfocus.com/archive/77/420755
37. [SJ-JOB] Application Security Architect, Maidenhead/ London
http://www.securityfocus.com/archive/77/420750
38. [SJ-JOB] Security Consultant, Frankfurt or Munich
http://www.securityfocus.com/archive/77/420752
39. [SJ-JOB] Security Engineer, Santa Clara
http://www.securityfocus.com/archive/77/420749
40. [SJ-JOB] Sr. Security Engineer, Dublin
http://www.securityfocus.com/archive/77/420697
41. [SJ-JOB] Technical Writer, Columbia
http://www.securityfocus.com/archive/77/420693
42. [SJ-JOB] Security Engineer, Dublin
http://www.securityfocus.com/archive/77/420694
43. [SJ-JOB] Sales Engineer, Any City
http://www.securityfocus.com/archive/77/420695
V. INCIDENTS LIST SUMMARY
---------------------------
1. WMF Threat OK , but no huge attack ... WHY ?
http://www.securityfocus.com/archive/75/421290
2. WMF Vulnerability Summary
http://www.securityfocus.com/archive/75/420902
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. WMF exploitation FAQ
http://www.securityfocus.com/archive/82/421260
2. RECON2006 - Call for paper
http://www.securityfocus.com/archive/82/421014
3. Did MS pull an Ilfak? (MS patch bindiff results)
http://www.securityfocus.com/archive/82/421015
4. Windows CE Address Book 2
http://www.securityfocus.com/archive/82/421017
5. Uninformed Journal Release Announcement: Volume 3
http://www.securityfocus.com/archive/82/420795
6. WMF - read Win3.1SDK Help!
http://www.securityfocus.com/archive/82/420839
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. patching servers...
http://www.securityfocus.com/archive/88/421403
2. audit trails for file access
http://www.securityfocus.com/archive/88/421005
3. SecurityFocus Microsoft Newsletter #272
http://www.securityfocus.com/archive/88/420784
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Hide internal address (Postfix)
http://www.securityfocus.com/archive/91/421374
2. IPS project - wanted translators
http://www.securityfocus.com/archive/91/421243
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: SpiDynamics
ALERT: Learn to Think Like a Hacker- Simulate a Hacker Breaking into Your Web Apps
The speed with which Web Applications are developed make them prime targets for attackers, often these applications were developed so quickly that they are not coded properly or subjected to any security testing. Hackers know this and use it as their weapon. Download this *FREE* test guide from SPI Dynamics to check for Web application vulnerabilities.
https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003P6V